Join me for another OAuth & OIDC masterclass. We will cover use cases, complexities, latest best practices, and high-security configuration options for OAuth in 4 live 3-hour sessions.
Early bird discount available for 10 more days buff.ly/wLedqA2 #appsec
09.04.2025 09:18 β π 3 π 1 π¬ 0 π 0
SecAppDev is now on Bluesky. If you want to stay up to date, make sure you follow us!
14.02.2025 17:37 β π 3 π 0 π¬ 0 π 0
This cheat sheet gives you an overview of current best practices for using OAuth 2.0. Grab a PDF copy here (buff.ly/4jCred1). If you want to learn more about these topics, this masterclass covers it all! buff.ly/3PnrZJ6 The early-bird rate has been extended for a few more days, so grab a ticket now!
29.01.2025 15:16 β π 7 π 0 π¬ 0 π 0
Breaking and securing OAuth 2.0 in frontends
Discover the underestimated threat of Cross-Site Scripting (XSS) in OAuth 2.0 Single Page Applications. Learn about hacks on frontend OAuth clients and explore solutions like the Backend-for-Frontendβ¦
Today, I'm doing back-to-back talks at NDC Security 2025. In this second talk, I'm discussing how a previous talk at NDC resulted in me joining as a co-author of the OAuth spec for browser-based apps. Grab the slides here: https://buff.ly/4fMgG8Z #appsec #infosec
23.01.2025 09:21 β π 16 π 4 π¬ 1 π 0
SEVEN things about API security
In this talk, we delve into key vulnerabilities from the OWASP API Security top 10, demonstrate a practical exploitation example, and discuss two real-world case studies to guide you in enhancingβ¦
I am talking about API security at NDC Security 2025. Using real-world cases, we discuss a couple of do's and don'ts that can help you secure your APIs. You can grab a copy of the slides here: https://buff.ly/46TtghZ #appsec #infosec
23.01.2025 08:02 β π 3 π 0 π¬ 0 π 0
I do have a couple of online courses available (courses.pragmaticwebsecurity.com). This live course is the most up-to-date version, which will eventually make it into the online courses (but that's an intense and time-consuming process).
06.01.2025 17:07 β π 1 π 0 π¬ 0 π 0
I am kicking off 2025 with a new live interactive training on OAuth 2.0 and OIDC. This course covers the latest best practices for browser-based apps, API security, and high-security OAuth configurations.
Early bird and group (3+) discounts available! Info & registration: https://buff.ly/3PnrZJ6
06.01.2025 13:05 β π 3 π 1 π¬ 1 π 1
Last week, I taught two 2-day classes, which is always insanely intense and really requires an enormous amount of energy. Fortunately, the feedback makes it worth it!
Now two weeks of doing some research and consulting. And of course, prepping the menu and trying out some dishes for the holidays!
10.12.2024 10:18 β π 3 π 0 π¬ 0 π 0
Awesome research! It's always crazy how many vulnerabilities you can still find by just reading RFCs π₯
05.12.2024 06:59 β π 7 π 2 π¬ 0 π 0
Supercharging OAuth 2.0 security
Discover how to apply OAuth 2.0 in high-security scenarios, exploring its latest security enhancements. Learn about advanced features like Resource Indicators, JAR, PAR, and DPoP, gaining theβ¦
Excited to be at the OWASP BeNeLux Days, with the wonderful security community. I will be speaking about Supercharging OAuth security slides here: https://buff.ly/4ikT64W), and doing a 1-day API security workshop. #appsec #infosec
28.11.2024 10:53 β π 7 π 1 π¬ 0 π 0
I'm in the process of creating a *web security* starter pack and need your help finding more webbies here. Please share and recommend folks passionate about web security in comments below so we can get this community started here π
go.bsky.app/Uf8dZhz
17.11.2024 10:12 β π 56 π 25 π¬ 16 π 0
In a couple of weeks, I'm teaching two live online workshops, both consisting of a mix between lectures, demos, quizzes, and hands-on lab sessions:
- Securing Angular apps on Dec 2-3 (https://buff.ly/3uX8Rv1)
- Bulletproof APIs on Dec 5-6 (https://buff.ly/48JQM2Y)
Hope to see you there! #appsec
12.11.2024 10:18 β π 4 π 0 π¬ 0 π 0
Trainer, Consultant, and Programming Architect with Focus on Angular, GDE for Angular
Advisor at Duende Software - @duendesoftware.com
Substack: http://lcamtuf.substack.com/archive
Homepage: http://lcamtuf.coredump.cx
wannabe hacker... he/him
π± grow your hacking skills https://hextree.io
Web security research from the team at PortSwigger.
About me?
| Website: https://mizu.re
| Tool: https://github.com/kevin-mizu/domloggerpp
| Teams: @rhackgondins, @FlatNetworkOrg, @ECSC_TeamFrance
| From: https://twitter.com/kevin_mizu
Web application security guy with a passion for OWASP's open source WAF projects and National Cyber Strategy.
Maintains "Swiss Cyber Security" starter pack and cherishes his small collection of medieval helmets.
Blogging at https://nastystereo.com
Co-Founder @shielder.com
CTF Player jbz.team
Cliff Jumping Lover (23mt max so far)
Penetration tester trying to perform novel research. You can find all of my write-ups and research at https://thomas.stacey.se.
Doing security research. For fun and profit...
about://inducebrowsercrashforrealz ππ₯οΈ
https://albertofdr.github.io/
IT-Security Researcher, Pentester and Bug Hunter. Passionate about π», π€½ββοΈ, βοΈ, πΈ and β½ #meinVfL
#Kaeferjaeger + H1 Ambassador
π https://security.lauritz-holtmann.de
Founder of #PasswordsCon. Above average interested in passwords & digital authentication. Online since 2400baud. I do security & privacy. Want me to speak at your conference / org? Reach out!
Encryption, HTTPS, certificates, web security, security UX, software engineering and management, TMI about parenting. Opinions are my own.
security enthusiast that loves hunting for bugs in the wild. co-founder and player of @justCatTheFish.
infosec at @google. opinions are mine.
From: https://twitter.com/terjanq